Hosted by Claire Pales
The Security Collective is the podcast for leaders tasked with, and interested in, securing technology, people, processes and data for the protection of all.
126 episodes · publishes weekly · latest 2023-02-01 · ~22 min/episode
Rank
#4109
Substance
55.0
/ 100
Breakdown
Scored 2026-07
Updated monthly
Across the index
#4109 of 6182
Substance
Top 66%
outscores 34% of the index
The Security Collective Podcast ranks #4109 on The B2B Podcast Index with a substance score of 55.0 out of 100, scored across 1 recent episode. It scores highest on guest caliber and conversational craft. The season drew a reasonable range of practitioners - working CISOs, a DevSecOps consultant, a compliance startup founder, an interim CISO - but the caliber is diluted by a cybersecurity fiction novelist, a university academic discussing micro-credentials, and a vendor evangelist (Proofpoint) whose insights are product-aligned. No guest is operating at notable scale or is a marquee industry name.
Averaged across 1 recently scored episode, with cited evidence.
The mashup format means no single topic is explored beyond surface level; several clips deliver generic advice (OWASP top 10, encryption at rest/in transit, trust-building in a new role) that most B2B security practitioners already know. The most substantive moments - Mark Bone's 'generic vs. specific threat' prioritisation and Paul McCarty's AppSec placement argument - are genuinely useful but brief and underdeveloped.
“focusing first on...generic issues. Things that are going to get us hacked just because we're on the Internet. Not things that are going to get us hacked because of the specific company we are”
“when I've seen application security be on the security side, it's typically orphaned, underfunded and understaffed”
Most content recycles well-worn cybersecurity talking points - people as the weakest link, OWASP basics, build trust in your first 90 days, audits are valuable. The 'very attacked person' framing is Proofpoint's own marketing concept, not an independent insight, and the Craig Ford segment on fiction-writing is irrelevant to B2B operators. Paul McCarty's stance that AppSec belongs in engineering rather than infosec is the episode's lone contrarian argument with real reasoning behind it.
“I'd say that it should probably be in the software engineering group just to take a stance on one side or the other”
“attackers aren't necessarily focusing on network diagrams anymore of your company in order to attack you. They're actually focusing on your people”
The season drew a reasonable range of practitioners - working CISOs, a DevSecOps consultant, a compliance startup founder, an interim CISO - but the caliber is diluted by a cybersecurity fiction novelist, a university academic discussing micro-credentials, and a vendor evangelist (Proofpoint) whose insights are product-aligned. No guest is operating at notable scale or is a marquee industry name.
“Paul McCarty was no exception. Across episodes 109 and 110, Paul shared his wisdom on DevSecOps”
“Craig Ford, returned for a chat in episode 106. My homework for this conversation was to read Craig's book Foresight”
Concrete numbers, metrics, timelines, and named case studies are almost entirely absent across all nine clips. Company names are occasionally mentioned (Immutable, Proofpoint, Wilson, Assurance Labs) but serve as biographical context rather than evidence. No dollar figures, breach statistics, or measurable outcomes appear anywhere in the transcript.
“nine times out of 10 and probably 99 times out of 100, that's a person that generates the weakness”
“I'm originally a Unix admin from the 90s that evolved. I took an opportunity in the early 2000s to work with the infosec team”
The host asks competent, structured questions - including a good binary that forces Paul McCarty to take a stance on AppSec placement - but there is no visible pushback, challenge, or productive disagreement across any of the nine clips. The mashup format inherently obscures follow-up quality, and several questions are framed so broadly that guests can answer with platitudes unchallenged.
“do you see the application security capability...should that capability be something that sits in the engineering teams...Or do you think that the AppSec people should be in the information security team?”
“I'm, um, hearing this term very attacked people, which sounds a bit violent, but who are very attacked people”
First period on the Index - history builds from here.
1 scored on substance · 60 tracked in total.
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/the-security-collective-podcast" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/the-security-collective-podcast/badge.svg" alt="Ranked #224 on The B2B Podcast Index" width="360" height="136" />
</a>Track The Security Collective Podcast's rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
The themes that come up most across this show's episodes.
Podcasts that dig into the same topics.